📦

edk_ii

Vendor: tianocore

Actively Exploited 0 CISA KEV List
PoC / Exploits 0 Code Available
Total RCEs 3 Remote Access
Total CVEs 13 Total Indexed
Avg. EPSS 0.84% Exploit Prob.
Latest CVE CVE-2021-28216 Aug 05

Security Vulnerability Index

Page 1 / 2
7.8 CVSS

BootPerformanceTable pointer is read from an NVRAM variable in PEI. Recommend setting PcdFirmwarePerformanceDataTableS3Support to FALSE.

EPSS: 0.42%
6.8 CVSS

Insufficient input validation in MdeModulePkg in EDKII may allow an unauthenticated user to potentially enable escalation of privilege, denial of service and/or information disclosure via physical access.

EPSS: 0.34%
5.5 CVSS

Stack overflow in XHCI for EDK II may allow an unauthenticated user to potentially enable denial of service via local access.

EPSS: 0.39%
9.8 CVSS

Buffer overflow in system firmware for EDK II may allow unauthenticated user to potentially enable escalation of privilege and/or denial of service via network access.

EPSS: 1.34%
7.8 CVSS

Logic issue in variable service module for EDK II/UDK2018/UDK2017/UDK2015 may allow an authenticated user to potentially enable escalation of privilege, information disclosure and/or denial of service via local access.

EPSS: 0.44%
6.8 CVSS

Stack overflow in DxeCore for EDK II may allow an unauthenticated user to potentially enable escalation of privilege, information disclosure and/or denial of service via local access.

EPSS: 0.50%
6.7 CVSS

Insufficient memory write check in SMM service for EDK II may allow an authenticated user to potentially enable escalation of privilege, information disclosure and/or denial of service via local access.

EPSS: 0.41%
6.0 CVSS

Stack overflow in corrupted bmp for EDK II may allow unprivileged user to potentially enable denial of service or elevation of privilege via local access.

EPSS: 0.43%
8.8 CVSS

Buffer overflow in BlockIo service for EDK II may allow an unauthenticated user to potentially enable escalation of privilege, information disclosure and/or denial of service via network access.

EPSS: 2.25%
7.8 CVSS

Improper configuration in system firmware for EDK II may allow unauthenticated user to potentially enable escalation of privilege, information disclosure and/or denial of service via local access.

EPSS: 0.42%